cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foricegram icegram

Direction: ascending
Jun 07, 2024

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2023-52119

CVE, Research URL

CVE-2023-52119

Date
Jan 05, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.18.
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2023-2398

CVE, Research URL

CVE-2023-2398

Date
Jun 12, 2023
Research Description
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2022-1776

CVE, Research URL

CVE-2022-1776

Date
Jun 27, 2022
Research Description
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2021-36832

CVE, Research URL

CVE-2021-36832

Date
Oct 19, 2021
Research Description
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2021-24941

CVE, Research URL

CVE-2021-24941

Date
Dec 21, 2021
Research Description
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2023-51532

CVE, Research URL

CVE-2023-51532

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.19.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024
Jul 26, 2024

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2024-39625

CVE, Research URL

CVE-2024-39625

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
Affected versions
Min -, max -.
Status
vulnerable
Aug 15, 2024
Aug 19, 2024

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2024-43344

CVE, Research URL

CVE-2024-43344

Date
Aug 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25.
Affected versions
Min -, max -.
Status
vulnerable
Jan 07, 2025

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2024-12302

CVE, Research URL

CVE-2024-12302

Date
Jan 06, 2025
Research Description
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable
Jan 26, 2025

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2025-24542

CVE, Research URL

CVE-2025-24542

Date
Jan 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icegram Icegram allows Stored XSS. This issue affects Icegram: from n/a through 3.1.31.
Affected versions
Min -, max -.
Status
vulnerable
May 16, 2025

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2024-13482

CVE, Research URL

CVE-2024-13482

Date
May 16, 2025
Research Description
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable

Icegram Engage &#8211; WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building # CVE-2024-13486

CVE, Research URL

CVE-2024-13486

Date
May 16, 2025
Research Description
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable